single - click account takeover by abusing insecure password reset link generation using the Host header(via host header injection) - http://localhost:3000/generateOTP
Web - SQL Injection Take over Takeover the account of user with email address - Demostuff
I have to create a Public url.